Data roles, handling, the data life cycle and compliance categories
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Objective 3.3 asks you to summarize how data is protected. The previous lesson took the data itself -- its types, states, classification and the techniques that protect it. This one takes everything around it: who is responsible for it, how it is marked and where it may go, the stages it passes through from creation to destruction, and the legal categories that attach obligations to it.
Why this matters
Most data breaches are not failures of encryption. They are failures of handling: a spreadsheet emailed to the wrong person, a laptop with an unencrypted export on it, a backup kept in a country it should never have reached, a decommissioned drive sold with the data still on it, records kept years after anyone needed them. Every one of those is a question this lesson answers -- who should have decided, what the label said, where the data was allowed to be, and when it should have been destroyed.
The exam asks it as "who should do this?" and "what should have happened at this stage?". Both have clean answers once the roles and stages are fixed in your head.
The lesson
Data owner, custodian and steward, and the controllers and subprocessors outside them
Inside the organisation:
- Data owner -- accountable for a dataset: its classification, who may access it, and how long it is kept. A senior business role in the department the data belongs to, not IT.
- Data custodian -- implements and operates the controls the owner specifies: storage, backups, encryption, granting the access the owner approved. Usually IT.
- Data steward -- responsible for quality, meaning and appropriate use; the person who knows what the fields mean and whether a proposed use fits the reason the data was collected.
- Data operator -- the least standardised term of the set. Read it as the person or team that works with the data day to day -- entering, processing and running the systems that use it -- within the rules the owner set and the controls the custodian runs.
Outside it, under privacy law:
- Data controller -- the party that decides why and how personal data is processed, and carries the legal obligations to the people it is about.
- Data processor -- processes personal data on the controller's behalf and on its instructions. Most SaaS vendors are processors.
- Data subprocessor -- a processor engaged by another processor: your payroll provider's hosting company, say. Under the GDPR a processor needs the controller's authorisation before engaging one and must pass on the same data protection obligations, which is why contracts ask for a list of subprocessors and notice of changes.
The distinctions the exam tests: owner decides, custodian implements -- if the storage administrator is deciding who may see a dataset, the roles have collapsed and that is the finding. And controller instructs, processor follows -- after a breach at a vendor, the controller usually still owes the duties to the people affected. Lesson 45 takes controller and processor further.
Marking and labelling, and handling data on endpoints
Marking is the classification visible to people: a header and footer on a document, a banner in an email, a watermark, a sticker on removable media. Labelling is the classification held as metadata that machines can act on: a sensitivity label that a DLP tool reads to block an upload, that triggers encryption, or that prevents printing. Good programmes do both, applied at creation, with defaults so that unlabelled data is not treated as public.
Endpoints are where handling most often fails, because that is where people copy, print, photograph and carry data. The controls:
- full-disk encryption on every laptop and phone, so a lost device is not a breach;
- DLP on the endpoint to stop labelled data going to USB drives, personal cloud storage or unapproved applications;
- removable media control -- blocked, or allowed only for encrypted, approved devices;
- mobile device management with a separate work container and the ability to wipe it remotely;
- keeping sensitive data on the server and giving people views of it rather than copies, where the work allows.
Geofencing, data location and placement, and the jurisdiction question
Data sovereignty is the principle that data is subject to the laws of the country where it is stored -- and, often, of the country whose law governs the company holding it. Consequences:
- some jurisdictions require certain data, often health, government or financial records, to stay within their borders;
- some restrict transfers of personal data to countries without adequate protection, so international transfers need a legal mechanism;
- a government may be able to compel access to data in its territory or held by a provider subject to its laws.
Data location is knowing where every copy is. It covers the primary store and also backups, replicas, logs and support access, which is where organisations get caught: the main database is in the right region and the disaster recovery copy is not.
Data placement is the decision about where data should live: which region, which system, which network zone. Keeping a regulated dataset in one region and one restricted segment, rather than in the general file share, is placement.
Geofencing enforces location with technology: allowing access to a dataset only from devices inside a country, blocking sign-ins from regions where nobody works, or locking a managed device that leaves a defined area. Location signals can be spoofed -- a VPN changes apparent location -- so geofencing is one layer, not a guarantee.
The life cycle from creation through distribution and retention to disposal
Data passes through five stages, and each has its own controls.
- Creation -- the point to classify and label, because it is the cheapest moment to do it. Also the point for minimisation: do not collect what you do not need.
- Management -- storage, access control, use and maintenance during the data's working life: encryption at rest, permissions set by the owner, monitoring of access.
- Distribution -- sharing, transmission and publication. Encryption in transit, approved sharing channels, DLP, and agreements with any third party who receives it.
- Retention -- keeping data as long as law, regulation or the business requires, and no longer. A retention schedule sets the period for each kind of data. A legal hold overrides it when litigation is expected, so relevant data must be preserved even past its scheduled deletion.
- Disposal -- destroying data so that it cannot be recovered: overwriting or cryptographic erasure where the media will be reused, physical destruction where it will not, and a certificate of destruction from any third party who does it. Lesson 33 covers sanitisation in detail.
The commonest failure is at stage four: data kept forever because deleting it felt risky. Data past its retention period is pure liability -- it can be breached, subpoenaed and demanded by its subjects, and it serves no purpose.
Health, personal, financial and children's data, and the standards that govern each
Some categories of data carry obligations set by someone outside the organisation.
- Health data. In the United States, HIPAA governs health information held by healthcare providers, insurers and their business associates. Under the GDPR, health data is a special category with stricter conditions for processing.
- Personal information. Privacy laws such as the GDPR in the EU, the UK GDPR, and state laws such as California's CCPA give individuals rights over their data and place duties on organisations that hold it.
- Financial data. Payment card data is governed by PCI DSS -- an industry standard enforced through contracts with the card brands, not a law. In the United States, GLBA covers customer data held by financial institutions, and SOX demands controls over the integrity of public companies' financial reporting.
- Children's data. Children get extra protection almost everywhere. In the United States, COPPA requires verifiable parental consent before collecting personal information online from children under 13. Where an online service offered directly to children relies on consent, the GDPR requires a parent's consent below a threshold age: 16 by default, and as low as 13 where a member state chooses.
- Intellectual property and legal data. Trade secrets lose protection if reasonable steps were not taken to keep them secret. Legal data -- contracts, privileged advice, material under legal hold -- carries preservation and confidentiality duties.
Standards such as ISO/IEC 27001 and PCI DSS sit alongside the law: some are voluntary, some are contractual, and auditors test against them. The habit for the exam is to identify the category of data first, because that tells you which rules apply.
What to take into the exam
- Owner decides, custodian implements, steward understands, operator works with it; controller instructs, processor follows, subprocessor follows the processor.
- Marking is for people, labelling is metadata for machines; endpoints need encryption, DLP and media control.
- Sovereignty follows storage location and covers backups, replicas, logs and support access; geofencing enforces location but can be spoofed.
- Create, manage, distribute, retain, dispose: classify at creation, keep no longer than required, and legal hold overrides the schedule.
- Identify the data category first: health, personal, financial, children's, intellectual property or legal.
Practise what you just read
1. A storage administrator is deciding who may see the finance department's dataset. What is the finding?
Select one
Show answer
B. The data owner, a senior business role, decides classification, access and retention, and the custodian, usually IT, implements and operates the controls the owner specifies. When the person running the storage decides who may see the data, the roles have collapsed, and that is the finding.
2. A SaaS payroll vendor suffers a breach of employees' personal data. Who usually still owes duties to those employees?
Select one
Show answer
D. The controller decides why and how personal data is processed and carries the legal obligations to the people it concerns. A processor acts on the controller's instructions, so a breach at the vendor does not transfer the controller's duties; it usually triggers them.
3. A database sits in the country the law requires, but its disaster recovery copy is replicated abroad. What has failed?
Select one
Show answer
B. Data sovereignty attaches the laws of the place where data is stored, and data location means knowing where every copy is: backups, replicas, logs and support access as well as the primary store. The disaster recovery copy in the wrong region is where organisations usually get caught.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.